Description
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Published: 2026-08-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Browser-side code execution via stored XSS
Action: Immediate Upgrade
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in Esri Portal for ArcGIS versions 11.5 and earlier. The flaw allows a remote attacker with administrative privileges to inject malicious script that is stored and later executed within the victim’s browser when the content is viewed. This can lead to the execution of arbitrary client‑side code, potentially exposing sensitive data or enabling further attacks against authenticated users. The CVSS score of 5.5 places the vulnerability in the medium severity range.

Affected Systems

Affected systems are Esri Portal for ArcGIS deployments running any of the identified versions 11.1, 11.3, or 11.5. All users of those releases are advised to apply the vendor’s patch or upgrade to the latest long‑term support release, as the issue is fixed in newer versions.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk, and the vulnerability requires the attacker to be a privileged administrator to perform the injection. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity is unknown. The attack vector is inferred to be remote, as the attacker can inject the script from any location using privileged access. Overall, the risk is moderate but mitigated by the requirement of administrative credentials.

Generated by OpenCVE AI on August 21, 2026 at 22:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Esri Portal for ArcGIS to the latest long-term support release to eliminate the stored XSS flaw.
  • Restrict administrative privileges to trusted users and audit administrative activity to reduce the chance of a privileged account being compromised.
  • Enforce strict input validation and output encoding for all user‑supplied data, and configure a content security policy to block execution of injected scripts.

Generated by OpenCVE AI on August 21, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Esri
Esri portal For Arcgis
Vendors & Products Esri
Esri portal For Arcgis

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.
Title stored cross site scripting issue in Esri Portal for ArcGIS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Esri Portal For Arcgis
cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2026-08-24T13:01:23.752Z

Reserved: 2026-08-03T19:22:01.732Z

Link: CVE-2026-69233

cve-icon Vulnrichment

Updated: 2026-08-24T12:54:09.487Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T21:17:04.023

Modified: 2026-08-26T16:54:26.617

Link: CVE-2026-69233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')